Oracle JDK 23 EOL March 18, 2025 – Risks & Support Options
What Happened on March 18, 2025
Oracle JDK 23, a non‑LTS release, reached its official end of life on March 18, 2025. The latest version in this line is 23.0.2. After this date, Oracle no longer provides public updates, security patches, or bug fixes for JDK 23. This includes both the base release and any subsequent updates.
For a full lifecycle overview of Oracle’s Java products, visit our Oracle software lifecycle page.
What Still Works — and What Stops
JDK 23 will continue to run existing applications exactly as they did before the EOL date. No code breaks simply because the vendor stopped support. However, the following services ceased as of March 18, 2025:
- Security patches: No new CVEs will be addressed by Oracle for this version. Any vulnerabilities discovered after that date remain unpatched.
- Bug fixes: Oracle will not release corrections for non‑security defects, even if they cause application instability.
- Commercial support: No access to Oracle’s support portal, patches, or technical assistance for JDK 23.
Because JDK 23 is not a Long‑Term Support (LTS) release, it was never intended for prolonged production use. Oracle’s LTS releases (e.g., JDK 17, JDK 21) receive years of updates. Non‑LTS releases like JDK 23 have a six‑month cadence and are designed for early adopters and testing.
The Real Risks of Running an Unsupported JDK
Staying on JDK 23 after EOL introduces several operational risks:
- Unpatched vulnerabilities: Without security fixes, your environment becomes increasingly exposed to exploits targeting known weaknesses in the JVM or standard libraries.
- Compliance gaps: Regulatory frameworks (PCI DSS, SOC 2, HIPAA) often require timely patching of critical software. Running an end‑of‑life runtime may fail audits or create non‑compliance findings.
- Integration friction: Third‑party libraries, monitoring agents, and container base images frequently drop support for obsolete JDK versions, making upgrades harder the longer you wait.
- No vendor escalation: If a production issue arises that Oracle attributes to a JDK 23 bug, you have no official channel for a fix.
Who Legitimately Stays on JDK 23?
Despite the risks, some organizations remain on JDK 23 for legitimate reasons:
- Stable workloads with no security concerns: Isolated, air‑gapped systems that process non‑sensitive data and never touch the internet may tolerate an unsupported runtime.
- Locked application dependencies: Proprietary or highly customized applications that only run on JDK 23 and cannot be upgraded without significant rework.
- Hardware constraints: Legacy infrastructure that cannot support a newer JDK due to OS or processor limitations.
- In‑progress migration: Teams that have already scheduled an upgrade but haven’t completed testing or deployment. In these cases, the EOL date is a hard deadline to accelerate.
How Third‑Party Support Keeps JDK 23 Maintained
For organizations that cannot upgrade immediately — or that prefer to defer the migration cost — third‑party maintenance provides a safe bridge. Providers such as 3rd Party Support can deliver:
- Security backports: Critical CVEs patched and delivered as custom builds tailored to your JDK 23 deployment.
- Bug fixes for high‑severity issues: Resolution of stability or performance defects that Oracle will no longer address.
- Extended support SLAs: Contractual commitments for response times and patch availability, typically at a fraction of Oracle’s last renewal cost.
- Lifecycle flexibility: You choose when to migrate, without being forced onto a new major version or subscription model.
Third‑party support is especially valuable for non‑LTS releases like JDK 23, where the vendor support window is inherently short. Instead of undergoing a disruptive upgrade every six months, you can maintain a stable runtime while your team plans a controlled move to an LTS version.
Next Steps
If you are still running Oracle JDK 23, start by inventorying all instances and assessing which workloads require immediate patching or compliance attention. For those that cannot be upgraded right away, consider a third‑party maintenance agreement to close the security gap.
Contact us for a no‑obligation discussion about extending support for your JDK 23 environment — or any other Oracle Java version that has reached end of life.
Get support for what you run
How we can help
Keep it supported after end of life
The vendor's date doesn't have to be yours. Our engineers keep Oracle JDK 23 running after official support ends — independent third-party support that covers most operational issues, typically at 40-70% below the last renewal quote.
Oracle OS software support →Migration services
When you do decide to move, we plan and execute the migration. Your current environment stays under vendor support while your contract is active — and if the renewal lapses mid-move, our third-party support covers most issues until the last workload is off it.
Migration & hybrid cloud services →24×7 remote administration
Short on hands to run it day to day? Our NOC engineers monitor, patch and administer your environment around the clock — incident response included, at a fraction of the cost of an in-house night shift.
24/7 operations & remote administration →More EOSL Alerts
VMware Site Recovery Manager 9.0: EOL September 2027
VMware Site Recovery Manager 9.0 reaches end of life on September 17, 2027. Learn what that means for your budget, migration timelines, and third-party support
August 17, 2026
VMware Cloud Foundation 9.0 EOL September 2027
Plan your budget now: VMware Cloud Foundation 9.0 ends support Sept 17, 2027. Compare upgrade, vendor extended support, and third-party support costs to stay se
August 17, 2026
VMware ESXi 9.0 EOL September 2027
VMware ESXi 9.0 ends support Sept 17, 2027 – 13 months away. Plan next year's budget: compare migration costs with third-party support savings of 40–70%.
August 17, 2026